FileVault policy automation not applying to existing Macs in HexnodeSolved

Participant
Discussion
5 days ago Sep 15, 2026

We’re trying to tighten FileVault enforcement across our Mac fleet in Hexnode.

Some users enabled FileVault manually before we started managing it through Hexnode, so we changed the policy to allow those users to turn FileVault off manually and then let Hexnode enable it again with the managed configuration/key escrow.

A couple of things I want to confirm:

If a user disables FileVault manually, will Hexnode automatically re-enable it on the next restart or login?

Is there a period where the Mac remains unencrypted before Hexnode enforces the policy again?

Replies (3)

Marked SolutionPending Review
Hexnode Expert
5 days ago Sep 15, 2026
Marked SolutionPending Review

Hi @v_collins ,

For a FileVault policy where users are allowed to turn off FileVault, Hexnode can still re-evaluate the device state and enforce the configured FileVault settings again.

The important behavior to account for is the timing:

  • When the user manually disables FileVault, the Mac may remain unencrypted temporarily.
  • Hexnode detects the non-encrypted state during policy evaluation/check-in.
  • The device is marked non-compliant in the Hexnode portal while FileVault is off.
  • FileVault enforcement is triggered again on the next applicable login, restart, or policy check-in, depending on the policy configuration and macOS behavior.

So yes, there can be a window where the device is unencrypted after the user manually disables FileVault. This is expected when the policy does not block users from disabling FileVault.

Regards,
Isabel Lora
Hexnode UEM

Marked SolutionPending Review
Participant
5 days ago Sep 15, 2026
Marked SolutionPending Review

That explains the disable/re-enable part. My bigger concern is fleet coverage. If the policy is attached to an automation using the “on Device Enrollment” trigger, will it also apply to Macs that are already enrolled if I later add them to the target group?

Marked SolutionPending Review
Hexnode Expert
5 days ago Sep 15, 2026
Marked SolutionPending Review

No. An automation with the “on Device Enrollment” trigger runs only when a device is newly enrolled and completes its initial scan. It does not retroactively apply to devices that were already enrolled before being added to the target group.

For full FileVault coverage, use both of these:

  • Directly associate the FileVault policy with the existing Mac device group from the Policies section. This applies the policy to the current fleet.
  • Keep the “on Device Enrollment” automation active. This ensures newly enrolled Macs receive the FileVault policy automatically during onboarding.

With this setup, existing Macs are covered through direct policy association, and future Macs are covered through enrollment automation.

Regards,
Isabel Lora
Hexnode UEM

Save